AC-12 Session Termination

Access Control

Low Moderate High

Description

The information system automatically terminates a remote session after [Assignment: organization-defined time period] of inactivity.\n

Supplemental Guidance

A remote session is initiated whenever an organizational information system is accessed by a user (or an information system) communicating through an external, non- organization-controlled network (e.g., the Internet).\n

Enhancements

(1) Automatic session termination applies to local and remote sessions.\n

Compliance Mappings

ISO 17799 (legacy)

11.3.211.5.5

COBIT 4.1 (legacy)

None.